OpenSSL Heartbleed Security Update
blog.heroku.com
blog.heroku.com
If they had, there wouldn't be any talk of HTTPS being a barrier in their leaked presentations.
That said, all of that encrypted traffic they've got stored up can now, thanks to this bug, be decrypted.
You could make the inference that, if they did have it, they were not making broad use of it.
That's why having an insider with sysadmin access and prestige for social engineering purposes is so dangerous.
So was the advice about going to war with the Army you had, not the one you'd wished you had.
Another potential vector are add-ons that use encrypted connections (for example Heroku Postgres). These also could have been targeted, in which case add-ons credentials would need to be regenerated.
Am I interpreting the certificate info wrong? [edit per official answer below: YES] (Are fresh certificates sometimes given much older start times? [edit: YES])
This blogpost doesn't clearly address *.herokuapp.com HTTPS service, as opposed to the custom-domains "ssl:endpoint" service.
However, this blogpost says, "As of Tuesday, April 8 at 15:55 UTC, all Heroku certificates and infrastructure have been updated and are no longer vulnerable"... while the certificate still superficially looks like it's almost 3 months old. Something isn't as it seems, I hope it's just the certificate age.
http://blog.digicert.com/2014/04/heartbleed-openssl-fix/
Excerpt: "Also, Busy IT Guy is right; it's a little disheartening to be listed as Unsafe after having done all the right things, just because the issue date didn’t get updated."
Our CA will eventually revoke the previous incarnations of our certificates, signed with the old private keys, making them invalid.
This [1] Seems to suggest that Firefox, for instance, only checks for EV certs?
[1] http://news.netcraft.com/archives/2013/05/13/how-certificate...
We generated new CSRs, with new private keys, but with the same dates and details as the originals. This let us get fresh certs without going through a full renewal.
Thanks for the prod.
Does anyone know if this is "actually" true?. By looking at the bug it seems you can dump up to 64 bytes at a time from the stack. Given that the attacker doesn't control were from the stack at all and looking at the code the top of the stack is probably holding some random structure, is it really possible for the attacker to retrieve the private key?
I just want to be sure before spending a bunch of money to replace re-issue all certs.
And is it actually possible that the top of the stack has your private key?